fast-import: forbid escaped NUL in paths
NUL cannot appear in paths. Even disregarding filesystem path limitations, the tree object format delimits with NUL, so such a path cannot be encoded by Git. When a quoted path is unquoted, it could possibly contain NUL from "\000". Forbid it so it isn't truncated. fast-import still has other issues with NUL, but those will be addressed later. Signed-off-by: Thalia Archibald <thalia@archibald.dev> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Thalia Archibald committed
Apr 14, 2024 at 01:12 UTC
be4d6a371e80e16ae02d1f258103493394e4c155
3 files changed
+4
Documentation/git-fast-import.txt
+1
@@ -661,6 +661,7 @@ and its value must be in canonical form. That is it must not:
661
662
The root of the tree can be represented by an empty string as `<path>`.
663
664
+`<path>` cannot contain NUL, either literally or escaped as `\000`.
665
It is recommended that `<path>` always be encoded using UTF-8.
666
667
`filedelete`
builtin/fast-import.c
+2
@@ -2270,6 +2270,8 @@ static void parse_path(struct strbuf *sb, const char *p, const char **endp,
2270
if (*p == '"') {
2271
if (unquote_c_style(sb, p, endp))
2272
die("Invalid %s: %s", field, command_buf.buf);
2273
+ if (strlen(sb->buf) != sb->len)
2274
+ die("NUL in %s: %s", field, command_buf.buf);
2275
} else {
2276
/*
2277
* Unless we are parsing the last field of a line,
t/t9300-fast-import.sh
+1
@@ -3300,6 +3300,7 @@ test_path_base_fail () {
3300
local change="$1" prefix="$2" field="$3" suffix="$4"
3301
test_path_fail "$change" 'unclosed " in '"$field" "$prefix" '"hello.c' "$suffix" "Invalid $field"
3302
test_path_fail "$change" "invalid escape in quoted $field" "$prefix" '"hello\xff"' "$suffix" "Invalid $field"
3303
+ test_path_fail "$change" "escaped NUL in quoted $field" "$prefix" '"hello\000"' "$suffix" "NUL in $field"
3304
}
3305
test_path_eol_quoted_fail () {
3306
local change="$1" prefix="$2" field="$3"